Security Advisory

CVE-2008-3910

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-09-04 17:00:00
Last updated 2024-08-07 09:53:00
Assigner mitre
State PUBLISHED

Description

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.